Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Microsoft, IBM advance Web services spec

Security is focus of proposal

By Ed Scannell
July 08, 2003
 

Building on their previous efforts to create a framework for producing secure and interoperable Web services, IBM, Microsoft, and several other leading software companies on Tuesday will announce a specification intended to help corporate users simplify identity management.

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Free IT resource

Attend the SOA Executive Forum: Breaking SOA Bottlenecks SOAExecForum.com/may2007

Sponsored by InfoWorld

The proposed WS-Federation specification features a set of Web services technologies intended to give developers a standard way of adding security capabilities to any Web service they build. The specification defines mechanisms that allow developers to manage and establish trust relationships across companies and domains using a variety of different types of security solutions, including support for federated identities, according to company officials.

"This will let companies tie their identity systems to each other in a way that lets them trade information back and forth about users and systems and then federate that data across the Internet no matter what security infrastructure they are using," said Steven VanRoekel, Microsoft's director of Web services, in Redmond, Wash.

By allowing corporate users with a variety of security solutions to interoperate, administrators can afford to authenticate a single employee just once, allowing that employee to work with Web services available from his or her company as well as those of the company's business partners.

"What this will do is provide a way for trust relationships to be established," said Carla Norsworthy, director of dynamic e-business technologies at IBM in Somers, N.Y.

"Users can carry out federate identity and not inconvenience users with remembering lots of passwords, [and] administrators can now do this on policy-based systems,'' Norsworthy said.

In April of last year IBM and Microsoft laid out a road map called "Security in a Web services World," which laid out the framework of specifications for WS-Federation. The WS-Federation specification builds on the foundation WS-Security, which includes WS-Policy, WS-Trust, and WS-SecureConversation. Working together, these specifications are intended to enable a complete model of security functions for Web services.

In a related announcement, Microsoft and IBM also are delivering a white paper entitled, "Federation of Identities in a Web Services World."  The white paper outlines the challenges associated with federated identity management as well as describes a Web services model that allows companies to issue and rely on information from other companies and domains. This new model also allows them to broker trust and attributes across domains in a more secure manner so as to maintain individual and business privacy, officials from the companies said.

IBM and Microsoft officials will be accepting feedback on the specification from across the breadth of the development community and expect to present the completed specification before industry groups deliberating on Web services such as the Web Services Interoperability (WS-I) and others "in the next several months."

During a keynote at the Burton Group's Catalyst conference in San Francisco on Tuesday, IBM will demonstrate early implementations of interoperability across IBM and Microsoft systems using WS-Federation. Norsworthy said IBM expects to deliver products based on the specification "towards the end of this year."

"I see this as the linchpin spec that explains how all the other pieces fit together. However, we still have specifications on privacy and authorization left to complete, but this one really pulls the whole picture together," Norsworthy said.

Microsoft will also show off early versions of the specification at this week's conference and will also deliver initial products that take advantage of the completed specification by the end of 2003, according to VanRoekel.





 


 
Ed Scannell is an editor at large at InfoWorld.
 

TOP NEWS:


»  Software piracy hurts the open-source community too
Many nations are beginning to see stolen proprietary software as a lost opportunity for open source software, whose development can encourage innovation and job growth

»  Intel readies slew of embedded chips based on Atom core
Intel is trying to increase performance and drop power consumption in more than 15 system-on-chips that use the Atom core

»  Microsoft surprise reorganization aimed at online woes
Microsoft's online troubles hint at larger vulnerability; the company is facing challenges in areas that have been a lock for many years

»  Attack code released for DNS bug
Security experts warn that this attack code may give cybercriminals a way to launch virtually undetectable phishing attacks

»  Parts of San Francisco network still locked out
Administrators are still locked out of the city's VoIP system and LANs within the Sheriff's Department and the Recreation & Park Department

»  Intel says Moblin update coming soon
Open-source effort set for mobile Linux should have an alpha-level release in a few weeks




Solutions to the Toughest IT Challenges in Remote Offices
Though small in size, remote offices face many of the same IT challenges as larger central offices. This Webcast zeroes in on the top line challenges to deliver information that can provide immediate benefits to your business. Sponsor: AMD and Dell

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist